Showing posts with label assessment. Show all posts
Showing posts with label assessment. Show all posts

Monday, January 11, 2010

BackTrack 4 Final Released

Remote-Exploit has announced that BackTrack4 Final has been released.



BackTrack 4 Final is out and along with this release come some exciting news, updates, and developments. BackTrack 4 has been a long and steady road, with the release of abeta last year, we decided to hold off on releasing BackTrack 4 Final until it was perfected in every way shape and form. With this release includes a new kernel, a larger and expanded toolset repository, custom tools that you can only find on BackTrack, and more importantly, fixes to all (well, most..) major bugs that we knew of.

You can download it at http://www.backtrack-linux.org/




Monday, September 28, 2009

FRHACK OS v1 alpha1 - LiveCD for Security and Penetration Testing

I've written often about the BackTrack suite of security assessment and penetration testing tools. Slap BackTrack on a bootable USB drive and you're ready to wreak security geek havoc anytime, anyplace.

Darknet reports the release of FRHACK OS v1 alpha1, an updated and tweaked version of BackTrack 4 that contains fixes and additional tools.

I can't wait to try it out. You have to be somewhat Linux-friendly to work with either BackTrack or FRHACK, but it's a good way for the Wintel crowd to get some exposure outside of their comfort area.

Linky



Friday, July 17, 2009

Nmap 5.0 Released

First released in 1997, Nmap quickly became a go-to tool for network and security practitioners to perform security auditing functions, explore their networks to find anomolies and open ports, and so on.

The newest version, 5.0, has just been released, and it adds a couple of features that could either be extremely beneficial or curiously troubling, depending on who is using them, and why.

Ncat and Ndiff allow for the transfer or redirection of traffic (gasp!) , and the ability to compare and contrast patterns from previous scans. While the latter could be useful to see what has changed (especially if your traffic is generally the same and you suddenly notice peaks and valleys), the former could be somewhat dangerous if used in a malicious manner. Of course, you could say that about nearly all networking and security toolsets.

For more info and to grab a copy, head over to Insecure.org .

Image via Taonas at wikimedia.org


Tuesday, July 7, 2009

MultiISO LiveDVD v1.0 – BackTrack, Knoppix & Ophcrack

If you're looking for a single Live DVD that runs some of our favorite tools, like BackTrack, Knoppix, and Ophcrack, perhaps this Darknet article on the availability of MultiISO LiveDVD is worthy of your time.

Comprised of a number of tools for pen testing, vulnerability assessment, network mapping and security recon, password cracking, and so on, MultiISO LiveDVD seems to be a nice collection of the following components.
  • Backtrack 3
  • Damn Small Linux (DSL) 4.2.5
  • GeeXboX 1.1
  • Damn Vulnerable Linux (Strychnine) 1.4 edition
  • Knoppix 5.1.1, MPentoo 2006.1
  • Ophcrack 1.2.2 (remastered to contain SSTIC04-5k [720MB] table sets)
  • Puppy Linux 3.01
  • Byzantine OS i586-20040404
Read more and find a link to the torrent here.

Wednesday, April 15, 2009

Lynis System and Security Tool for UNIX

Hack A Day reports that Lynis 1.2.6 has been released.

Unlike many assessment tools, Lynis doesn't provide just a view of the security posture of your UNIX system. With a scan that includes configuration checks, installed packages, and other key areas for the well-rounded sysadmin, Lynis will give you a holistic view of the challenges to be corrected, whether they are patch-related, improper configs that compromise system hardening, or existing malware dumps that somehow got past your defenses.

Like other good tools such as back|track, Lynis can run from a USB drive or a live CD/DVD distro, so you don't need to perform an install. Another benefit is that Lynis doesn't make changes - it just observes and reports, so you don't need to worry that you'll somehow disrupt your highly-efficient change management process.

Lynis 1.2.6 released - UNIX System and Security Auditing Tool



Friday, April 10, 2009

Nessus 4 in Your Easter Basket

In case you're grossed out by the squishy stuff in the center of Cadbury eggs, or PETA has convinced you that biting the ears off of a hollow chocolate bunny is so very, very wrong, here's an Easter offering that all of us security geeks can embrace. Nessus 4 is out!

Woo hoo!


I'm especially eager to play with the PCI-DSS compliance check additions, to see if they truly identify issues that could lead to bad things happening, or if they just flag the kinds of issues that the credit card industry thinks are important. Ka-pow!

Check out their blog if you want to know more about what's new.

Nessus Version 4 Released